This URL gets the policy details (including attack set and response actions) for the specific IPS policy.
Resource URL
GET /ipspolicy/<policy_id>
Request Parameters
URL Parameters:
| Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| policy_id | IPS policy id | Number | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
| Field Name | Description | Data Type |
|---|---|---|
| PolicyDescriptor | Baseline IPS policy details | Object |
Details of PolicyDescriptor:
| Field Name | Description | Data Type |
|---|---|---|
| PolicyName | Baseline IPS policy name | String |
| Description | Policy description | String |
| IsVisibleToChildren | Is policy visible to child domain | Boolean |
| InboundRuleSet | Inbound policy rule set | String |
| OutboundRuleSet | Outbound policy rule set | String |
| AttackCategory | Attack category | Object |
| OutboundAttackCategory | Outbound attack category | Object |
| DosPolicy | DoS policy | Object |
| DosResponseSensitivityLevel | DoS response sensitivity level | Number |
| IsEditable | Is policy editable | Boolean |
| Timestamp | Time stamp at which the policy was added | String |
| VersionNum | Policy version number | Number |
| IsLightWeightPolicy | Is light weight policy configured | Boolean |
Details of object in AttackCategory:
| Field Name | Description | Data Type |
|---|---|---|
| ExpolitAttackList | List of exploit attacks | Array |
Details of object in ExpolitAttackList:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP id of the attack | String |
| severity | Attack severity, number between 0 & 9 | Number |
| isSeverityCustomized | Is attack severity customized | Boolean |
| isEnabled | Is attack enabled | Boolean |
| isAlertCustomized | Is alert customized | Boolean |
| isRecommendedForSmartBlocking | Is attack recommended for smart blocking | Boolean |
| AttackResponse | Attack response | Object |
| notification | Notifications configured | Object |
| protocolList | List of protocols | Array |
| applicationsImpactedList | List of applications impacted | Array |
| attackVector | List of attack vectors | Array |
| benignTriggerProbability | Attack benign trigger probability | String |
| target | Attack target, can be "Server" or "Client" | String |
| blockingType | Blocking type, can be "Attack Packet" | String |
| subCategory | Attack sub category | String |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| isAttackCustomized | Is attack customized | Boolean |
Details of object in AttackResponse:
| Field Name | Description | Data Type |
|---|---|---|
| TCPReset | TCP reset option, can be “DISABLED” / “SOURCE” / “DESTINATION” / “BOTH” | String |
| isTCPResetCustomized | Is TCP reset customized | Boolean |
| isICMPSend | Send ICMP host unreachable to Source | Boolean |
| isICMPSendCustomized | Send ICMP host unreachable to Source customized | Boolean |
| mcafeeNACNotification | NAC notification configured, can be “DISABLED” / “ALL_HOSTS” / “MCAFEE_NAC_UNMANAGED_HOSTS” | String |
| isMcafeeNACNotificationEnabled | Is NAC notification enabled | Boolean |
| isQuarantineCustomized | Is quarantine customized | Boolean |
| isRemediateEnabled | Is remediate enabled | Boolean |
| blockingOption | Blocking option configured, can be “DISABLE” / “ENABLE” / “ENABLE_SMART_BLOCKING” | String |
| isBlockingOptionCustomized | Is blocking option customized | Boolean |
| isCapturedPrior | Should application data be captured prior to attack | Boolean |
| isCapturedPriorCustomized | Should application data be captured prior to attack customized | Boolean |
| action | Action to be taken on attack, can be “DO_NOTHING” / “SEND_ALERT_AND_LOG_PACKETS” / “SEND_ALERT_ONLY” | String |
| isLogCustomized | Is logging customized | Boolean |
| flow | Customixe flow, can be “SINGLE_FLOW” / “FORENSIC_ANALYSIS” | String |
| isFlowCustomized | Customize flow type | Boolean |
| isNbytesCustomized | Is logging N bytes in each packet customized | Boolean |
| numberOfBytesInEachPacket | Number of bytes to be logged in each packet | Object |
| loggingDuration | Packet logging duration | Object |
| TimeStamp | Time stamp | String |
Details of object in numberOfBytesInEachPacket (Can be either of the below mentioned):
| Field Name | Description | Data Type |
|---|---|---|
| LogEntirePacket | Log entire packet | Object |
| CaptureNBytes | Capture N bytes | Object |
Details of object in CaptureNBytes:
| Field Name | Description | Data Type |
|---|---|---|
| NumberOfBytes | Number of bytes to log | Number |
Details of object in loggingDuration (Can be either of the below mentioned):
| Field Name | Description | Data Type |
|---|---|---|
| AttackPacketOnly | Log attack packet only | Object |
| CaptureNPackets | Capture N packets | Object |
| CaptureTimeDuration | Capture for a time duration | Object |
| RestOfFlow | Capture rest of flow | Object |
Details of object in CaptureNPackets:
| Field Name | Description | Data Type |
|---|---|---|
| npackets | Log n packets | Number |
Details of object in CaptureTimeDuration:
| Field Name | Description | Data Type |
|---|---|---|
| time | Capture time | String |
| timeUnit | Time unit, can be "SECONDS" / "MINUTES" / "HOURS" / "DAYS" | String |
Details of object in notification:
| Field Name | Description | Data Type |
|---|---|---|
| isEmail | Is notification configured through email | Boolean |
| isPager | Is notification configured through pager | Boolean |
| isScript | Is notification configured through script | Boolean |
| isAutoAck | Is notification configured through auto ack | Boolean |
| isSnmp | Is notification configured through SNMP | Boolean |
| isSyslog | Is notification configured through syslog | Boolean |
| isEmailCustomized | Is notification through email customized | Boolean |
| isPagerCustomized | Is notification through pager customized | Boolean |
| isScriptCustomized | Is notification through script customized | Boolean |
| isAutoAckCustomized | Is notification through auto ack customized | Boolean |
| isSnmpCustomized | Is notification through SNMP customized | Boolean |
| isSyslogCustomized | Is notification through syslog customized | Boolean |
Details of object in DosPolicy:
| Field Name | Description | Data Type |
|---|---|---|
| LearningAttack | List of learning attacks | Array |
| ThresholdAttack | List of threshold attacks | Array |
| TimeStamp | Time stamp | String |
Details of object in LearningAttack:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP ID of the attack | String |
| isSeverityCustomized | Is attack severity customized | Boolean |
| severity | Attack severity, number between 0 & 9 | Number |
| isBlockingSettingCustomized | Is blocking customized | Boolean |
| isDropPacket | Drop DoS attack packets of this attack type when detected | Boolean |
| isAlertCustomized | Is alert customized | Boolean |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String |
| timeStamp | Time stamp | String |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| notification | Notification to be sent via | Object |
| isAttackCustomized | Is DoS learning attack customized | Boolean |
Details of object in ThresholdAttack:
| Field Name | Description | Data Type |
|---|---|---|
| attackName | Attack name | String |
| nspId | NSP id of the attack | String |
| isSeverityCustomized | Is attack severity customized | Boolean |
| severity | Attack severity, number between 0 & 9 | Number |
| isThresholdValueCustomized | Is threshold value customized | Boolean |
| isThresholdDurationCustomized | is threshold duration customized | Boolean |
| ThresholdValue | Threshold values | Number |
| ThresholdDuration | Threshold Interval (Seconds) | Number |
| isAlertCustomized | Is alert customized | Boolean |
| isSendAlertToManager | Is alert notification to be sent to Manager configured | String |
| TimeStamp | Time stamp | String |
| Notification | Notification to be sent | Object |
| direction | Attack direction, can be "INBOUND" / "OUTBOUND" / "BOTH" | String |
| isAttackCustomized | Is DoS threshold attack customized | Boolean |
Example
Request
GET https://%3CNSM_IP%3E/sdkapi/ipspolicy/0
Response
{
"PolicyDescriptor":
{
"PolicyName": "IpsPolicy",
"Description": "To test the IPS policy",
"IsVisibleToChildren": true,
"InboundRuleSet": "TestIPS",
"OutboundRuleSet": "Null",
"AttackCategory":
{
"ExpolitAttackList":
[
{
"attackName": "FTP: VMware Flaw in NAT Function",
"nspId": "0x4050b400",
"severity": 7,
"isSeverityCustomized": false,
"isEnabled": true,
"isAlertCustomized": false,
"isRecommendedForSmartBlocking": false,
"AttackResponse":
{
"TCPReset": "DISABLED",
"isTcpResetCustomized": false,
"isICMPSend": false,
"isICMPSendCustomized": false,
"mcAfeeNACNotification": "DISABLED",
"isMcAfeeNACNotificationEnabled": false,
"isQuarantineCustomized": false,
"isRemediateEnabled": false,
"blockingOption": "DISABLE",
"isBlockingOptionCustomized": false,
"isCapturedPrior": true,
"isCapturedPriorCustomized": false,
"action": "SEND_ALERT_ONLY",
"isLogCustomized": false,
"isFlowCustomized": false,
"isNbytesCustomized": false,
"numberOfBytesInEachPacket":
{
"LogEntirePacket":
{
}
}
},
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"protocolList":
[
"ftp"
],
"benignTriggerProbability": "1 (Low)",
"blockingType": "attack-packet",
"subCategory": "code-execution",
"direction": "INBOUND",
"isAttackCustomized": false
}
]
},
"OutboundAttackCategory":
{
},
"DosPolicy":
{
"LearningAttack":
[
{
"attackName": "TCP Control Segment Anomaly",
"nspId": "0x40008700",
"isSeverityCustomized": false,
"severity": 7,
"isBlockingSettingCustomized": false,
"isDropPacket": false,
"IsAlertCustomized": false,
"isSendAlertToManager": true,
"direction": "BOTH",
"notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"isAttackCustomized": false
}
],
"ThresholdAttack":
[
{
"attackName": "Too Many Inbound TCP SYNs",
"nspId": "0x40008c00",
"isSeverityCustomized": false,
"severity": 6,
"isThresholdValueCustomized": false,
"isThresholdDurationCustomized": false,
"ThresholdValue": 2000,
"ThresholdDuration": 5,
"isAlertCustomized": false,
"isSendAlertToManager": false,
"Notification":
{
"isEmail": false,
"isPager": false,
"isScript": false,
"isAutoAck": false,
"isSnmp": false,
"isSyslog": false,
"isEmailCustomized": false,
"isPagerCustomized": false,
"isScriptCustomized": false,
"isAutoAckCustomized": false,
"isSnmpCustomized": false,
"isSyslogCustomized": false
},
"direction": "INBOUND",
"isAttackCustomized": false
}
],
"TimeStamp": "2012-06-20 18:44:55.000"
},
"DosResponseSensitivityLevel": 0,
"IsEditable": false,
"Timestamp": "2012-06-20 18:44:55.000",
"VersionNum": 1,
"IsLightWeightPolicy": false
}
}
Error Information
Following error code is returned by this URL:
| S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
| 1 | 404 | 1108 | Invalid policy Id |